These features help you prevent, detect, fine tune, and manage the protection configuration for your Linux systems.
Prevention — Avoiding threats
Configure Threat Prevention features to stop intrusions before they gain access to your environment.
Viewing managed tasks — You can view the managed custom tasks from your ePO - On-prem server.
6010 Engine support — Pre-packaged with the latest 6010 engine that provides enhanced detection capabilities.
Extra.DAT files — Download and install Extra.DAT files to provide protection from a major virus outbreak.
Detection — Finding threats
On-Access Scan — Scans files and directories for threats whenever users access them.
On-Demand Scan — Schedules a scan on files and directories at specific times. Each on-demand scan contains its own policy settings. You can also run Full Scan or Quick Scan on a Linux system.
Activity logging for on-demand scan — You can now enable activity logging on-demand scan to track all the files scanned by the on-demand scan task.
Policy-Based On-Demand Scan client tasks — Run a Quick Scan or Full Scan on the Endpoint Security Client from ePO - On-prem. Configure the behavior of these scans in the policy settings for an on-demand scan.
Profile based scanning — Allows you to add processes to high risk or low risk profile and configure protection settings accordingly for scanning.
Support for Trellix® Global Threat Intelligence — Supports Trellix GTI, a heuristic network lookup for suspicious files when running on-access scanning and on-demand scanning.
Response — Handling threats
Use product log files, automatic actions, and other notification features to determine the best way to handle detections.
Actions — Configure actions to take when detections occur.
Alerts — Specify how Threat Prevention notifies you when detections occur, including alerting options and filtering alerts by severity to limit alert traffic.
Tuning — Monitoring, analyzing, and fine-tuning your protection
Monitor and analyze your configuration to improve system and network performance, and enhance virus protection, if needed. Use these tools and features:
Support for CPU Throttled On-Demand Scan — Allows you to configure and control the CPU usage when running on-demand scan task. To use this feature, you must install Trellix® Endpoint Security10.6.1 or later extensions. For more information about the ePO extension update build numbers, see Trellix Endpoint Security (ENS) for Linux installation guide.
Queries, dashboards, and server tasks (ePO - On-prem) — Monitor scanning activity and detections.
Log files (Trellix Endpoint Security (ENS) for Linux Client) — View a history of detected items. Analyzing this information might reveal that you must enhance your protection or change the configuration to improve system performance.
Custom log path — Customize the destination for product log files. This feature prevents disk space contention on system partitions and supports compliance requirements.
Scheduled tasks — Modify client tasks (such as Product Update) and scan times to improve performance by running them during nonpeak times.
Content repositories — Reduce network traffic over the enterprise Internet or intranet by moving the content file repository closer to the clients.
Scan policies — Analyze log files or queries and modify policies to increase performance or virus protection, if necessary. For example, you can improve performance by configuring exclusions.
Exclusion of files and directories from scanning — Excludes specific files and directories from on-access scanning and on-demand scanning using criteria such as file type, extension, file age, or wildcards.
Option to scan network volumes and compressed files — Exclude or include mounted network volumes and compressed files from scanning.
Option to retain client-side exclusions — Overwrites or retains the client exclusion list for on-access scanning in a managed environment.
Common extensions to manage Windows, Macintosh and Linux systems — Use Trellix Endpoint Security (ENS) extensions as common extensions to manage policies for your Windows, Macintosh, and Linux systems.
Common ePO - On-prem dashboard and queries — Use the ePO - On-prem dashboard to view the status of managed Windows, Linux, and Mac systems.
Support for Trellix ePO - SaaS — Support for ePO - SaaS to manage policies for your Linux systems.
Enable debug logging from client interface — Enable debug logging for Threat Prevention using the client interface.
Viewing managed tasks — You can view the managed custom tasks from your ePO - On-prem server.
Extra.DAT files — Download and install Extra.DAT files to provide protection from a major virus outbreak.
Access Protection — Allows you to protect files and processes from threats.
Migration of Host Intrusion Prevention Linux custom policies — You can migrate Linux custom policies from Host Intrusion Prevention to Trellix ENS for Linux Threat Prevention.
Support for SELinux confinement — Trellix Endpoint Security (ENS) for Linux Threat Prevention and Firewall functions appropriately in SELinux policy confined mode.
Medium DAT support — Trellix Endpoint Security (ENS) for Linux now supports Medium DAT (for content) that reduces the footprint of the product.
Container Vulnerability Scanner — Trellix Endpoint Security (ENS) for Linux Container Vulnerability Scanner is a command line tool that enables you to identify the vulnerabilities present in your docker images.
Log compression support — Trellix Endpoint Security (ENS) for Linux Threat Prevention and Firewall now stores these logs in compressed format:
mfetpd,mfeoasmgr,odsreport,mfeespd,mfefwd.Exploit Prevention for Linux — Trellix Endpoint Security (ENS) for Linux supports Exploit prevention for Linux in a managed environment. It brings in content support that can automatically define access control policies and settings for processes, files, and directories. By restricting access to specific files and directories, you can protect your systems from vulnerabilities. Content support brings in signatures that can automatically enforce the above policies and can be updated on a regular cadence. The individual signatures can then be managed from ePO and configured to block and report access.
For violations, you can either report access violations or disable it.
Note
Trellix Endpoint Security (ENS) for Linux doesn't support expert rules for Exploit Prevention.